/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2025-27018

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-27018

CGA ID

CGA-hjhg-834c-qpc6

Severity

Unknown

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider.

When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0.

Users are recommended to upgrade to version 6.2.0, which fixes the issue.

References

  • https://images.chainguard.dev/security/CGA-hjhg-834c-qpc6

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs